Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
OpenSSH trojaned; is ebuild affected?
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
slinkan
n00b
n00b


Joined: 08 May 2002
Posts: 5
Location: SWE

PostPosted: Fri Aug 02, 2002 8:24 am    Post subject: OpenSSH trojaned; is ebuild affected? Reply with quote

Just read over at LWN that the latest SSH is Trojaned on openbsd's ftp, does anyone know if the latest ebuild is affected by this trojan?

Or for that matter ANY ebuild of openSSH?

thanks!

regards
slinkan
Back to top
View user's profile Send private message
Chris W
l33t
l33t


Joined: 25 Jun 2002
Posts: 972
Location: Brisbane, Australia

PostPosted: Fri Aug 02, 2002 8:51 am    Post subject: Reply with quote

That modification does not appear in the openssh-3.4p1.tar.gz in my distfiles copy (from the Gentoo IBiblio site).
_________________
Cheers,
Chris W
"Common sense: The collection of prejudices acquired by age 18." -- Einstein
Back to top
View user's profile Send private message
slinkan
n00b
n00b


Joined: 08 May 2002
Posts: 5
Location: SWE

PostPosted: Fri Aug 02, 2002 8:58 am    Post subject: Great Thanks Reply with quote

Chris W wrote:
That modification does not appear in the openssh-3.4p1.tar.gz in my distfiles copy (from the Gentoo IBiblio site).


Good, I wasn't sure how to check, looked around in the portage dir, but couldn't find the gzip file...

Thank you very much!

regards
slinkan

[edit] AAAAWW!! dammit, just saw that this already had been discussed! Sorry for beeing a n00b and not using search! [/edit]
Back to top
View user's profile Send private message
Soupy
n00b
n00b


Joined: 22 Jul 2002
Posts: 9

PostPosted: Fri Aug 02, 2002 1:54 pm    Post subject: Reply with quote

If you, theoretically, managed to end up with the trojaned openssh sources when you tried to run that ebuild, it should have failed the md5 sum check and not built.
Back to top
View user's profile Send private message
Zu`
l33t
l33t


Joined: 26 May 2002
Posts: 716
Location: BE

PostPosted: Sun Aug 04, 2002 8:57 pm    Post subject: Reply with quote

Soupy wrote:
If you, theoretically, managed to end up with the trojaned openssh sources when you tried to run that ebuild, it should have failed the md5 sum check and not built.


Correct -- MD5 can really save you a lot of trouble, in cases like this.
Back to top
View user's profile Send private message
pjp
Administrator
Administrator


Joined: 16 Apr 2002
Posts: 20586

PostPosted: Mon Aug 05, 2002 6:13 pm    Post subject: Reply with quote

Just in case anyone else finds this... there are several threads on this topic already:
Posted: Wed Jun 26th, 2002 14:07 Post subject: OpenSSH 3.4
Posted: Wed Jun 26th, 2002 20:35 Post subject: [gentoo-announce] GLSA: OpenSSH (The official Gentoo Security announcement)
Posted: Thu Aug 01st, 2002 07:44 Post subject: Trojan in OpenSSH 3.4p1(locked in favor of this next one)
Posted: Thu Aug 01st, 2002 06:19 Post subject: FYI: OpenSSH Trojan.

This thread was "Posted: Fri Aug 02nd, 2002 02:24".

I'm mainly trying to demonstrate why using search is important.
_________________
Quis separabit? Quo animo?
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum